Courseiva
IT Risk Identification →mediumMultiple Choice

CRISC IT Risk Identification Practice Question

A risk practitioner is analyzing the threat landscape for a hospital's connected medical devices. The devices run legacy operating systems that cannot be patched and are accessible from the clinical network. Which factor MOST increases the likelihood of exploitation?

⚠ Common exam trap

The trap here is selecting a control weakness such as untested response or awareness training when the question asks specifically about likelihood of exploitation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The devices are connected to the clinical network and run unpatched legacy operating systems.

Likelihood of exploitation increases when a vulnerable asset is also reachable by a threat actor. The legacy, unpatched operating systems provide known exploitable weaknesses, and connectivity from the clinical network provides the path to reach them. Together they create a direct, low-friction attack opportunity. The other factors affect response readiness, coordination, or unrelated vectors and do not create the same immediate exposure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The devices are manufactured by multiple vendors with varying support lifecycles.

    Why it's wrong here

    Vendor diversity complicates asset management and patching coordination, but it does not by itself create the exposure. The scenario already states the devices cannot be patched, so the multi-vendor factor is secondary. The dominant likelihood driver is the combination of unpatched software and network reachability, which directly enables exploitation regardless of vendor count.

  • ✗

    The hospital's incident response plan has not been tested in the last twelve months.

    Why it's wrong here

    An untested response plan affects the impact and recovery speed after an incident, not the likelihood that an exploit occurs. While it is a legitimate weakness, it does not create an attack path or vulnerability. The scenario asks specifically about likelihood of exploitation, so response readiness is a downstream concern rather than the primary driver.

  • ✓

    The devices are connected to the clinical network and run unpatched legacy operating systems.

    Why this is correct

    Unpatched legacy systems expose known vulnerabilities, and network connectivity from the clinical network provides an attack path to reach them. Together these factors directly raise the likelihood that a threat actor can exploit the devices. This combination is the most significant likelihood driver because it removes both the barrier of unknown weaknesses and the barrier of inaccessibility.

  • ✗

    Clinical staff have not received security awareness training on phishing emails.

    Why it's wrong here

    Phishing awareness is relevant to social engineering vectors, but the scenario describes devices reachable directly from the clinical network with unpatched software. That direct technical exposure is a more immediate likelihood driver than user behavior. Awareness training would not mitigate exploitation of a network-reachable, unpatched medical device.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.